Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
97 commits
Select commit Hold shift + click to select a range
2631ff3
feat(cla): require a Contributor License Agreement on pull requests
debpalash Oct 1, 2026
a7052b9
ci: pin third-party actions to commit SHAs and track them with Depend…
debpalash Oct 1, 2026
33ab3ae
chore(governance): add CODEOWNERS, repository-settings guide, and ref…
debpalash Oct 1, 2026
37ce4db
ci(security): block leaked and placeholder commit identities on PRs
debpalash Oct 1, 2026
e5e135a
chore(contact): publish only hi@, partner@ and security@voicestudio.sh
debpalash Oct 1, 2026
901895b
docs(maintainers): require the CLA status and record the hardening ch…
debpalash Oct 1, 2026
2d934e2
fix(cla): close review gaps before rollout
debpalash Oct 1, 2026
f9429c9
docs(changelog): file the hardening entries under Added and CI with t…
debpalash Oct 2, 2026
14c1c00
docs(license): state the CLA open-source commitment as the CLA words it
debpalash Oct 2, 2026
f92b3b4
ci(security): fail PRs that credit AI agents or carry agent identities
debpalash Oct 2, 2026
0bd9bec
ci(docker): publish release images only when the GitHub Release is pu…
debpalash Oct 2, 2026
5be86db
fix(review): point review bots at live Electron paths and guard them
debpalash Oct 2, 2026
08952ab
docs(security): support only the latest 0.5.x and document API auth
debpalash Oct 2, 2026
1228f64
build(deps): align root TypeScript with Electron on 7.x
debpalash Oct 2, 2026
256ae92
ci: pin bun to the packageManager version in CI, audit and Docker
debpalash Oct 2, 2026
fbde425
build: keep one workspace lockfile and one dependency range per package
debpalash Oct 2, 2026
5bd1a30
ci: run the frontend node:test suites in the required test job
debpalash Oct 2, 2026
c644fb7
docs(deploy): name the ROCm 7.2.4 torch build in the constraints comment
debpalash Oct 2, 2026
1605af5
build: drop the unused PyInstaller spec and runtime dependency
debpalash Oct 2, 2026
228fbb8
docs(contributing): match setup, structure and checks to the repo
debpalash Oct 2, 2026
33477f0
fix(issues): route new bug and install reports to needs-triage
debpalash Oct 2, 2026
f058ee8
docs(releasing): document the five-target matrix, analytics secrets a…
debpalash Oct 2, 2026
1f908ad
docs(scripts): drop the nonexistent validate-install-docs companion
debpalash Oct 2, 2026
555fdd2
chore(install): remove the duplicate install-redirect worker
debpalash Oct 2, 2026
84821ee
docs(license): say commercial use is free and link the Pro plans
debpalash Oct 2, 2026
5a5efdb
docs(agents): state the current release line, Intel Mac scope and san…
debpalash Oct 2, 2026
eb7a732
fix(backend): single-source browser origin policy and real port repor…
debpalash Oct 2, 2026
548f086
fix(i18n): drop orphan zh-CN player keys and reject renderer locale o…
debpalash Oct 2, 2026
14cdd44
fix(performance): apply speed/quality tiers to the OmniVoice sidecar
debpalash Oct 2, 2026
72df26a
docs(install): replace Tauri-era platform guides with Electron instru…
debpalash Oct 2, 2026
20d4867
docs(docker): fix HF cache mount, tag semantics and analytics wording
debpalash Oct 2, 2026
8594fa9
docs(updates): document stable-only desktop updates
debpalash Oct 2, 2026
afec17a
docs: describe the Electron tree, version source and path authorization
debpalash Oct 2, 2026
2000a5a
docs: mark migration-era notes historical and retire Tauri release docs
debpalash Oct 2, 2026
615f868
fix(generate): outlast the backend budget before the client aborts
debpalash Oct 2, 2026
63d6a6b
fix(dev): keep dev:api on loopback and follow OMNIVOICE_PORT
debpalash Oct 2, 2026
8b931a5
chore(i18n): prune shared catalog keys no code references
debpalash Oct 2, 2026
f4c980a
fix(i18n): keep the seconds unit in five locales and cover the runtim…
debpalash Oct 2, 2026
9bd8137
ci(security): say gitleaks fails CI rather than blocking merge
debpalash Oct 2, 2026
1a22ca8
ci(electron): drop the preview update feed from packaging
debpalash Oct 2, 2026
efd951d
fix(uninstall): remove the Electron app's folders, not only Tauri's
debpalash Oct 2, 2026
010299b
fix(speech): retire native dictation control aimed at a dead port
debpalash Oct 2, 2026
85af646
fix(cla): fail closed on unverified, hidden, and superseded contributors
debpalash Oct 2, 2026
8d3b2a1
fix(ci): match only agent identities and catch agent names and sessio…
debpalash Oct 2, 2026
ffd503c
docs(maintainers): require pull requests on main and state the CLA se…
debpalash Oct 2, 2026
7c0b5d2
fix(docker): pull released images and mount the cache the image uses
debpalash Oct 2, 2026
59a28bb
fix(prefs): drop preference reads that nothing ever writes
debpalash Oct 2, 2026
eefc149
fix(generate): typecheck the shared generate budget module
debpalash Oct 2, 2026
787f7a6
fix(updates): remove the Preview update channel
debpalash Oct 2, 2026
ee4a259
Merge branch 'fix/audit-docs' into chore/consistency-sweep
debpalash Oct 2, 2026
96d7e36
Merge branch 'fix/audit-install' into chore/consistency-sweep
debpalash Oct 2, 2026
65b5045
Merge branch 'fix/audit-tooling' into chore/consistency-sweep
debpalash Oct 2, 2026
49791be
docs: point i18n rules at the catalog the app loads and drop backend.…
debpalash Oct 2, 2026
6fa3f13
docs(backend): point stale Tauri references at the Electron equivalents
debpalash Oct 2, 2026
4746316
fix(windows): start the Electron runtime under a non-English profile …
debpalash Oct 2, 2026
4ee7c57
Merge branch 'fix/audit-code' into chore/consistency-sweep
debpalash Oct 2, 2026
86850d3
docs: default Docker quick starts to :stable and finish the audit fol…
debpalash Oct 2, 2026
42e75b8
fix(cla): count tool addresses only in co-author trailers or on verif…
debpalash Oct 2, 2026
d16d954
fix(ci): run the identity gate from the base branch, require it, and …
debpalash Oct 2, 2026
2179fb4
fix: close the sweep review gaps (stable ROCm docs, older-backend tie…
debpalash Oct 2, 2026
8f9e037
Merge branch 'chore/repo-hardening' into chore/consistency-sweep
debpalash Oct 2, 2026
744bd6c
docs(changelog): record the consistency sweep
debpalash Oct 2, 2026
9f2f079
docs(macos): keep the Intel support statement the smoke job checks, w…
debpalash Oct 2, 2026
3eb8422
fix(uninstall): accept only the exact runtime record the app writes, …
debpalash Oct 2, 2026
322e67f
docs(macos): drop the duplicated token and troubleshooting sections, …
debpalash Oct 2, 2026
70d26b6
fix(generate): follow backend timeouts an operator raised when sizing…
debpalash Oct 2, 2026
9d07b44
fix(generate): keep the newest budget report, wait briefly for one in…
debpalash Oct 2, 2026
ee2de2d
fix(ci): credit a person in 'by an LLM engineer', rewrite only listed…
debpalash Oct 2, 2026
391ff69
Merge branch 'chore/repo-hardening' into chore/consistency-sweep
debpalash Oct 2, 2026
723a1d2
fix(ci): flag generic AI credit unless a person's role follows it
debpalash Oct 2, 2026
0d36b67
fix(uninstall): run only an uninstaller in the install folders, never…
debpalash Oct 2, 2026
e749be4
Merge branch 'chore/repo-hardening' into chore/consistency-sweep
debpalash Oct 2, 2026
4c948fc
fix(ci): flag generic AI credit only when a tool word follows or the …
debpalash Oct 2, 2026
475c7fc
fix(uninstall): run the registered uninstaller from any install folde…
debpalash Oct 2, 2026
144297f
Merge remote-tracking branch 'origin/chore/repo-hardening' into chore…
debpalash Oct 2, 2026
484d0db
fix(uninstall): skip an uninstaller other users can modify in an elev…
debpalash Oct 2, 2026
37bd07e
fix(ci): check the bash uninstall script with bash, not sh
debpalash Oct 2, 2026
44e56a1
chore: remove unused Remotion player integration
debpalash Oct 2, 2026
183ff5a
docs: record Remotion dependency removal
debpalash Oct 2, 2026
52c7622
fix: ship application and T3 Code license notices in installers
debpalash Oct 2, 2026
5f5d615
docs: correct model license assumptions in engine decisions
debpalash Oct 2, 2026
bb46910
fix: stop asserting unverified demo audio licenses
debpalash Oct 2, 2026
4ee2bff
fix: clarify application license scope across commercial surfaces
debpalash Oct 2, 2026
dd61df7
Merge main after repository hardening rollout
debpalash Oct 3, 2026
6e275a0
fix(uninstall): refuse elevated app removal before cleanup
debpalash Oct 3, 2026
aeb38c2
Merge commit '6e275a0bbec300f65e35688f13e48a9eb0ba2b8a' into fix/pro-…
debpalash Oct 3, 2026
d5cc622
fix(runtime): verify setup after optional path repair errors
debpalash Oct 3, 2026
377aff0
feat(about): credit supported model authors and upstream terms
debpalash Oct 3, 2026
f1ff381
Merge commit 'd5cc622093540a99ddee86e2f4c3fdf8e67486df' into fix/pro-…
debpalash Oct 3, 2026
07d6099
docs(licensing): audit locked PyAV binary dependencies
debpalash Oct 3, 2026
ca9bb74
Merge current main after consistency sweep squash
debpalash Oct 3, 2026
b1d8c57
chore(licensing): gate model inventory completeness in CI
debpalash Oct 3, 2026
a403393
docs(licensing): remove private service operations from public spec
debpalash Oct 3, 2026
979a097
fix(pro): exclude existing free workflows from paid benefits
debpalash Oct 3, 2026
3151fa9
fix(licensing): cover additional model defaults and aliases
debpalash Oct 3, 2026
ddce4be
fix(licensing): cover runtime model defaults and clarify paid scope
debpalash Oct 3, 2026
823226f
docs(licensing): separate technical feasibility from rights approval
debpalash Oct 3, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
16 changes: 16 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -39,6 +39,10 @@ metadata and the backend fallback mirror it.

### Added

- Track model licence evidence and unresolved commercial-use reviews, with CI coverage for catalogue dependencies and backend repository defaults (#2587)

- About credits supported speech models and conversions, with upstream terms and required Higgs Audio and Llama notices (#2587)

- MCP agents can design a voice from a text description and reuse it by `profile_id` (`describe_voice`, `design_voice`) (#2368) — thanks @thelselutopia!
- Dictation vocabulary hint in Settings → Dictation shortcut: names and jargon that Faster Whisper, MLX Whisper and OpenAI-compatible engines should expect (#2395) — thanks @m061i6!
- Cheaper Inference is available as an optional LLM provider (#2325) — thanks @aiapienthusiast!
Expand All @@ -54,6 +58,17 @@ metadata and the backend fallback mirror it.
- Pull requests ask their opener and every commit author and co-author to sign a one-time Contributor License Agreement by comment; the contributing guide explains how (#2556)

### Changed
- Keep existing recipes, watch folders and remote compute out of Pro benefit lists, and stop describing voice cloning as a paid unlock (#2587)
- Keep private licensing-service operations out of the public client protocol draft (#2587)
- Clarify in Pro, export and enterprise text that the application licence does not grant model or generated-output rights, in all 21 languages (#2587)

- Remove unsupported automatic MIT licence claims from bundled demo metadata and generation scripts (#2587)

- Correct historical OmniVoice commercial-licence claims and require the rights gate as well as technical smoke tests for engine acceptance (#2587)

- Include the application licence notice and T3 Code MIT notice in desktop installers (#2587)

- Remove the unused Remotion player integration and dependency while keeping the existing media playback providers (#2587)
- Audio quality and Voice controls open as compact popovers from the Synthesize box on Clone and Voice Design (#2419)
- The Synthesize button shows its keyboard shortcut as key chips inside the button (#2419)
- The language menu stays within the window instead of clipping at the edges (#2419)
Expand Down Expand Up @@ -87,6 +102,7 @@ metadata and the backend fallback mirror it.
- Removed three hidden settings that nothing could set; the `OMNIVOICE_PRONUNCIATION` and `OMNIVOICE_TEXT_NORMALIZATION` switches remain (#2578)

### Docs
- Record the locked PyAV wheels' FFmpeg build flags, bundled codecs and unresolved redistribution terms (#2587)
- Maintainer guide for repository settings that can't live in code; the licence notice scope and the contributing guide's list of network calls match the current app (#2556)
- Contact addresses are now hi@voicestudio.sh (general and licensing), partner@voicestudio.sh (partnerships) and security@voicestudio.sh (security reports) (#2556)
- Chinese README now matches the Electron installation and migration guide (#2377) — thanks @lg114!
Expand Down
16 changes: 16 additions & 0 deletions LICENSE-NOTICE.md
Original file line number Diff line number Diff line change
Expand Up @@ -55,9 +55,25 @@ weights as CC-BY-NC. Its `audio_tokenizer/LICENSE` contains separate Boson
Higgs Audio 2 and Meta Llama community terms. A commercial license for
VoiceStudio-owned code does not replace any of those terms.

The maintained About panel displays selected model credits and required literal
Higgs Audio and Llama attribution text. See [model credit sources](docs/model-credits.md)
for evidence and remaining gaps. These visible credits do not establish complete
notice compliance or permission for a particular use.

The [model licence records](backend/config/model_licenses.json) distinguish
inspected non-commercial terms from unreviewed upstream metadata. A false
commercial-use flag includes unresolved review; it is not a claim that every
listed model forbids commercial use. No commercial clearance is asserted by
the initial inventory.

Third-party dependencies retain their own licenses. See `bun.lock`, `uv.lock`,
and `native/desktop-bridge/Cargo.lock` for the resolved set.

The locked PyAV 15.1.0 wheels bundle FFmpeg and x264/x265 libraries. PyAV's source
licence alone does not describe those binaries' terms. The
[wheel audit](docs/licensing/pyav-15.1.0-audit.md) records their hashes, build flags,
upstream licence-label patch, and unresolved redistribution requirements.

### Reference

The full canonical text of the GNU Affero General Public License, Version 3 is
Expand Down
3 changes: 2 additions & 1 deletion backend/assets/samples/demo/dubbing/manifest.json
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,8 @@
"version": "0.3.0",
"rendered_by": "omnivoice engine + ffmpeg showwaves",
"rendered_at": "2026-08-12T19:47:29Z",
"license": "MIT (synthetic, no third-party IP)",
"license": "NOASSERTION",
"license_review_required": true,
"source": {
"code": "en",
"label": "English",
Expand Down
Loading
Loading